What Causes Intune Policy Tattooing Issues?
Intune policy tattooing occurs when configuration policies that have been deleted or unassigned from the Microsoft Intune admin center continue to enforce their settings on managed devices. This happens because the necessary Delete commands in SyncML (Synchronization Markup Language) are not being sent to devices, leaving policies "tattooed" in the Windows registry and continuing to control device behavior.
The most common root cause is invalid assignment filters in your Intune tenant. When a configuration profile references a deleted or corrupted assignment filter, it can block the entire deletion pipeline for all policies across your tenant. This means that even unrelated policies may fail to be properly removed from devices, creating widespread tattooing issues.



